Third-Party Cyber Risk Engineer II
Listed on 2026-03-06
-
IT/Tech
Cybersecurity, Data Security
Job Title
Third-Party Cyber Risk Engineer II
LocationOH - Columbus
What you'll doAs a Third-Party Cyber Risk Engineer II, you will independently and collaboratively manage cybersecurity risks across the Bank's third party ecosystem. You will lead technical assessments of third party services and clearly communicate findings to business partners and vendors. You will also help advance the team's efficiency and quality by introducing AI and automation into assessment, monitoring, and review processes. You'll partner with technology teams to design and implement modern solutions that strengthen the Third Party Cyber Risk program.
The Third Party Cyber Risk Engineer II is a technically strong cybersecurity professional who improves operational efficiency and performs indepth reviews of vendor environments, AIenabled capabilities, automated assessment outputs, and cloud architectures. The role supports Western Alliance Bank's Third Party Cyber Risk program by identifying material risks, validating control effectiveness, and ensuring alignment with regulatory requirements, internal security standards, and enterprise AI governance.
Success requires an analytical, skeptical mindset that helps uncover hidden risks among the Bank's third parties.
This role requires strong engineering, process improvement skills, knowledge of security frameworks, experience assessing third party cyber risk, and the ability to communicate complex technical topics across cyber, risk, and business teams. This position is inoffice only.
Responsibilities- Perform technical cybersecurity assessments of third party vendors, including cloud security, IAM, application and data security, network security, security governance, and incident response capabilities.
- Evaluate evidence and due diligence materials, including automated assessment outputs, SOC reports, penetration tests, policies, procedures, and AIrelated documentation, ensuring accuracy and completeness.
- Manage identified cyber risks using a riskbased approach, documenting control gaps and monitoring remediation through the third party lifecycle.
- Develop and implement automation, dashboards, and AIenabled enhancements to improve assessment efficiency, evidence analysis, and overall program operations.
- Support incident response involving third parties and help secure SaaS platforms by configuring monitoring tools, advising business teams, and driving remediation of compliance issues.
- Produce clear technical findings and executive level reporting and communicate risks with internal stakeholders and external vendors.
- Maintain and improve program documentation, including policies, standards, and procedures.
- Coordinate with SMEs to develop accurate, timely responses to due diligence inquiries from customers, rating agencies, and prospective clients, reflecting the Bank's security posture.
- 3+ years of experience in cybersecurity, security engineering, or third party/vendor risk management, ideally within a regulated industry.
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field.
- Entry level to intermediate knowledge of general Financial Services or Banking is preferred.
- Solid understanding of authentication protocols SAML, SSO, and LDAP. Solid understanding of concepts regarding SIEM, SOAR, Firewall, Proxies, SSL/TLS, Secure Mail Gateways, Application Firewalls, NAC, Vulnerability Scanners, and EDR.
- Intermediate to advanced understanding of logging infrastructure concepts: syslog; log parsing; log de-duping; methods for log pulling; RFC 5424; CEF Format; JSON; key value pair format; log enrichment; log maintenance; log troubleshooting.
- Solid understanding of load balancers, DNS, SMTP, etc. for troubleshooting application functionality.
- Intermediate to advanced knowledge of NIST, MITRE and Administration of either or all of an IT Automation platform, SOAR, Firewall, IAM platform, SIEM, cloud cyber defense platform etc.
- Strong technical skills across cloud and application security, IAM/Zero Trust, network and endpoint security, and data protection.
- Experience applying AI and automation (e.g., Power Automate) to improve workflows such as evidence analysis, document review, task execution, and reporting; additional experience building analytics using Power BI preferred.
- Knowledge of AI/ML security risks-including LLM governance, data ingestion controls, modelrisk considerations-and experience reviewing SOC reports, automated assessment outputs, and technical evidence.
- Working knowledge of security frameworks such as ISO 27001/27002, NIST CSF, NIST SP 80053, SOC reporting, and SIG/SCA.
- Strong communication, organization, and attentiontodetail skills, with the ability to manage multiple assessments and cross functional deadlines.
- Relevant certifications (CISA, CRISC, CISM, CISSP, CTPRP) required.
- Experience with vendor risk and security platforms (e.g., Service Now, Security Scorecard, Process Unity, Recorded Future) preferred.
We offer all the important things…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).